3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-38757
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.

CVE-2021-41871
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes it possible to place a stored XSS payload. This is executed if an administrator views the System Event Log.

CVE-2021-27352
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.

CVE-2021-20120
Arris SurfBoard SB8200 Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.

CVE-2021-43198
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, stored XSS is possible.

CVE-2021-24394
Easy Testimonial Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection

CVE-2021-24671
MX Time Zone Clocks Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2021-45026
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2021 2 PoCs

ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).

CVE-2021-24511
Product Feed on WooCommerce for Google, Awin, Shareasale, Bing, and More Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

CVE-2021-27695
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.

CVE-2021-43742
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.

CVE-2021-28000
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows remote attackers to execute arbitrary code via crafted payloads entered into the Name and Address fields.

CVE-2021-24735
Compact WP Audio Player Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack.

CVE-2021-25107
Form Store to DB Web Windows
N/A
UNKNOWN
EPSS
12.1%
2021 CWE-79 1 PoC

The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowing unauthenticated attacker to perform Cross-Site Scripting attacks against admin

CVE-2021-3318
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.

CVE-2021-31537
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.2%
2021 1 PoC

SIS SIS-REWE Go before 7.7 SP17 allows XSS: rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and /rewe/prod/web/rewe_go_check.php (version and all other parameters).

CVE-2021-24925
Modern Events Calendar Lite Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24642
Scroll Baner Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 1 PoC

The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSS

CVE-2021-24212
WooCommerce Help Scout Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.5%
2021 CWE-434 2 PoCs

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

CVE-2021-31903
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.